Executive brief
Goobi viewer is a web application used to display digitized library and archival materials. A security flaw in its core component allowed unauthorized users to send commands directly to the underlying search database. This could result in the theft of restricted documents, the modification of metadata, or the complete deletion of the search index, potentially causing significant data loss and service disruption.
Technical details
The Goobi viewer REST endpoint 'POST /api/v1/index/stream' failed to perform authentication (CWE-306) and forwarded arbitrary Solr streaming expressions to the backend Solr server without restriction. A remote, unauthenticated attacker can exploit this by sending malicious POST requests containing streaming expressions. This allows for full read access to indexed documents (bypassing IP or license restrictions), data modification via update() expressions, or permanent data deletion via delete() expressions. The vulnerability was addressed by removing the affected endpoint in version 26.04.1.
Affected products
- intranda viewer-core >= 4.8.0, <= 26.04
Timeline
- 2020-07-02: other: Vulnerability introduced in commit 6bfb1cb
- 2026-05-07: patched: Version 26.04.1 released
- 2026-05-08: disclosed: Initial advisory publication
- 2026-05-13: advisory: GHSA published
References
- https://github.com/intranda/goobi-viewer-core/security/advisories/GHSA-2rgp-f66f-4499
- https://github.com/intranda/goobi-viewer-core/commit/326980f24ce1e7cfabf658dd5f615934ca68ebbd
- https://github.com/intranda/goobi-viewer-core/releases/tag/v26.04.1
- https://github.com/intranda/goobi-viewer-core/commit/6bfb1cbd4250b0b347e84a80f38e8bf46acac705
- https://api.github.com/repos/intranda/goobi-viewer-core/security-advisories/GHSA-2rgp-f66f-4499